Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android HIGH 7.8
CVE-2018-11266

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper input validation can lead to an i…

Patch available
Fix from $1,950 2018-11-27
A3002ru Firmware CRITICAL 9.8
CVE-2018-13315

Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthent…

No fix yet
Fix from $2,300 2018-11-26
Dnsdist MEDIUM 5.9
CVE-2018-14663

An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing data such that the addition of…

Fix: after 1.3.2
Fix from $1,600 2018-11-26
Httl CRITICAL 9.8
CVE-2018-19530

HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses XStream unsafely when conf…

Fix: after 1.0.11
Fix from $2,300 2018-11-26
Httl CRITICAL 9.8
CVE-2018-19531

HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses java.beans.XMLEncoder unsa…

Fix: after 1.0.11
Fix from $2,300 2018-11-26
Mosquitto HIGH 7.5
CVE-2018-12543EPSS 36%

In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, …

Fix: after 1.5.2
Fix from $1,950 2018-11-15
Android MEDIUM 6.5
CVE-2018-9347

In function SMF_ParseMetaEvent of file eas_smf.c there is incorrect input validation causing an infinite loop. This could lead to a remote temporary …

Patch available
Fix from $1,600 2018-11-14
Android HIGH 7.8
CVE-2018-9523

In Parcel.writeMapInternal of Parcel.java, there is a possible parcel serialization/deserialization mismatch due to improper input validation. This c…

Patch available
Fix from $1,950 2018-11-14
Chrome HIGH 8.8
CVE-2018-6074

Failure to apply Mark-of-the-Web in Downloads in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to bypass OS level controls via a cra…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Chrome CRITICAL 9.6
CVE-2018-17472

Incorrect handling of googlechrome:// URL scheme on iOS in Intents in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to escape the <if…

Fix: 70.0.3538.67+
Fix from $2,300 2018-11-14
Prtg Network Monitor HIGH 8.8
CVE-2018-19204

PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS command…

Fix: 18.3.44.2054+
Fix from $1,950 2018-11-12
Recursor MEDIUM 5.9
CVE-2018-14644

An issue has been found in PowerDNS Recursor from 4.0.0 up to and including 4.1.4. A remote attacker sending a DNS query for a meta-type like OPT can…

Fix: after 4.1.4
Fix from $1,600 2018-11-09
Prime Collaboration MEDIUM 6.5
CVE-2018-15450

A vulnerability in the web-based UI of Cisco Prime Collaboration Assurance could allow an authenticated, remote attacker to overwrite files on the fi…

Mitigation only
Fix from $1,600 2018-11-08
Video Surveillance Media Server MEDIUM 6.5
CVE-2018-15449

A vulnerability in the web-based management interface of Cisco Video Surveillance Media Server could allow an unauthenticated, remote attacker to cau…

Mitigation only
Fix from $1,600 2018-11-08
Mindoc HIGH 8.8
CVE-2018-19114

An issue was discovered in MinDoc through v1.0.2. It allows attackers to gain privileges by uploading an image file with contents that represent an a…

Fix: after 1.0.2
Fix from $1,950 2018-11-08
Fabric Operating System MEDIUM 5.5
CVE-2018-6433

A vulnerability in the secryptocfg export command of Brocade Fabric OS versions before 8.2.1, 8.1.2f, 8.0.2f, 7.4.2d could allow a local attacker to …

Fix: 7.4.2d / 8.0.2f+
Fix from $1,600 2018-11-08
Debian Linux HIGH 7.5
CVE-2018-16472

A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inhe…

Fix: after 1.0.1
Fix from $1,950 2018-11-06
Android HIGH 7.5
CVE-2018-9362

In processMessagePart of InboundSmsHandler.java, there is a possible remote denial of service due to improper input validation. This could lead to re…

Patch available
Fix from $1,950 2018-11-06
I18n HIGH 7.5
CVE-2014-10077

Hash#slice in lib/i18n/core_ext/hash.rb in the i18n gem before 0.8.0 for Ruby allows remote attackers to cause a denial of service (application crash…

Fix: 0.8.0+
Fix from $1,950 2018-11-06
Adaptive Security Appliance Software HIGH 8.6
CVE-2018-15454

A vulnerability in the Session Initiation Protocol (SIP) inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Th…

Fix: 6.1.0.7 / 6.2.0.6+
Fix from $1,950 2018-11-01
Gluster Storage MEDIUM 6.5
CVE-2016-2125EPSS 9%

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to wh…

Fix: 4.3.13 / 4.4.8+
Fix from $1,600 2018-10-31
Debian Linux MEDIUM 6.5
CVE-2018-14661

It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vuln…

Mitigation only
Fix from $1,600 2018-10-31
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-15318

In BIG-IP 14.0.0-14.0.0.2, 13.1.0.4-13.1.1.1, or 12.1.3.4-12.1.3.6, If an MPTCP connection receives an abort signal while the initial flow is not the…

Fix: after 14.0.0.2
Fix from $1,950 2018-10-31
Big Ip Local Traffic Manager HIGH 7.5
CVE-2018-15319

On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.6, malicious requests made to virtual servers with an HTTP profile can cause the TMM to …

Fix: after 14.0.0.2
Fix from $1,950 2018-10-31
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2018-15323

On BIG-IP 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, in certain circumstances, when processing traffic through a Virtual Server with an associated MQTT prof…

Fix: after 14.0.0.2
Fix from $1,600 2018-10-31
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2018-15324

On BIG-IP APM 14.0.0-14.0.0.2 or 13.0.0-13.1.1.1, TMM may restart when processing a specially crafted request with APM portal access.

Fix: after 14.0.0.2
Fix from $1,600 2018-10-31
Merge HIGH 7.5
CVE-2018-16469

The merge.recursive function in the merge package <1.2.1 can be tricked into adding or modifying properties of the Object prototype. These properties…

Fix: 1.2.1+
Fix from $1,950 2018-10-30
Kdcproxy HIGH 7.5
CVE-2015-5159

python-kdcproxy before 0.3.2 allows remote attackers to cause a denial of service via a large POST request.

Fix: 0.3.2+
Fix from $1,950 2018-10-30
A Tuning HIGH 7.8
CVE-2018-10711

The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and Rest…

Fix: 1.0.6.2 / 1.0.35.1+
Fix from $1,950 2018-10-30
Sd 845 Firmware HIGH 7.8
CVE-2018-11872

Improper input validation leads to buffer overwrite in the WLAN function that handles WMI commands in Snapdragon Mobile in version SD 845, SD 850, SD…

Mitigation only
Fix from $1,950 2018-10-29